Cisco Secure Client Vulnerability Allows CRLF Injection Attacks

CVE-2024-20337
8.2HIGH

Key Information

Vendor
Cisco
Status
Cisco Secure Client
Vendor
CVE Published:
6 March 2024

Badges

😄 Trended👾 Exploit Exists📰 News Worthy

Summary

The vulnerability CVE-2024-20337 in Cisco Secure Client allows for CRLF injection attacks, potentially enabling an attacker to access sensitive information or execute arbitrary code in a user's browser. Exploiting this vulnerability could lead to the attacker obtaining a valid SAML authentication token, which they could use to establish a remote access VPN session with the affected user's privileges. While there are currently no known exploitations of this vulnerability, Cisco has released updated versions of Secure Client to address this flaw.

Affected Version(s)

Cisco Secure Client = 4.9.00086

Cisco Secure Client = 4.9.01095

Cisco Secure Client = 4.9.02028

News Articles

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit exists.

  • Vulnerability started trending.

  • First article discovered by Help Net Security

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database0 Proof of Concept(s)4 News Article(s)
.